Ask any information technology (IT) professional from the help desk operator to the chief technology officer in any company, and they will tell you that security is one of their primary concerns.
You can almost be guaranteed that they will rattle off a list of exotic titles in your direction, with words like intrusion detection systems, anti-spam, firewalls, antivirus and reverse proxies being bandied about as a measure of how secure their IT infrastructure is.
However, one area that many IT departments neglected to factor in when they crafted their security strategy was the human factor, security experts said.
'Security in a large enterprise can be analogous to a chain - if there is one weak link [through an employee], the enterprise may be at risk,' said Derek Manky, a security researcher for Fortinet. 'This may be through an innocent mistake - as most cases are - or through actual malicious intent.'
The answer to this was education and a solid IT security policy, experts said.
Michael Gazeley, managing director of Network Box, a managed security service provider, said it was a matter of time before the sheer volume of spam, viruses, worms and trojan horses hitting corporate networks every day compromised even the most robust security system.